First published: Sun Oct 16 2016(Updated: )
It was discovered that the Hotspot component of OpenJDK did not check types of System.arraycopy() function arguments src and dest in certain cases. An untrusted Java application or applet could use this flaw to corrupt virtual machine's memory and bypass Java sandbox restrictions.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK | =1.6.0-update121 | |
Oracle JDK | =1.7.0-update111 | |
Oracle JDK | =1.8.0-update101 | |
Oracle JDK | =1.8.0-update102 | |
Oracle JRE | =1.6.0-update121 | |
Oracle JRE | =1.7.0-update111 | |
Oracle JRE | =1.8.0-update101 | |
Oracle JRE | =1.8.0-update102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.